SANS Internet Storm Center; Cooperative Network Security Community - Internet Security - isc
Here are couple of updates regarding the latest 0-day.
As noted in Microsoft's advisory, Windows Server 2008 and Vista (both SP0 and SP1) are affected as well. The exploit for Windows Vista is publicly available now as well, but most malicious web sites still use the exploit I analyzed yesterday, so they are attacking only Windows XP and Windows 2003 machines.
It also appears that more attackers are now using this – we received log files showing that attackers using SQL injection are now. The SQL Injection attacks are similar to those we've described multiple times before (see SANS Internet Storm Center; Cooperative Network Security Community - Internet Security - isc, for example). The important part includes the target URL that is injected:
…
rtrim(convert(varchar(4000),['+@C+']))+''<script src=****></script>''')FETCH NEXT FROM
…
This domain is not listed by Shadowserver yet. The 1.js script on the domain links to multiple other HTML documents of which one is called ie7.htm. You guessed it, it contains the latest 0-day exploit for Internet Explorer.
If executed successfully, the script will download the binary from ****. This is a game password stealer which has sporadic detection (Virustotal. MD5: 4b1c340d2c21e02e0f59f9a490705d2e Trojan-GameThief.Win32.Magania.amtu Trojan:Win32/Hogst.B TR/Dialer.tth) – there are some big names still missing it.
In any case, the attackers are picking this quickly so make sure that you are following recommendations from Microsoft's advisory which will help reduce exposure or, if you can, use an alternative browser until this has been fixed.
PS: Sorry, I couldn't find any new topics about this one. Deleted website info to protect the stupid. Also, stop using IE, for fucks sake.
XI Wiki


